diff --git a/internal/certacme/certifiers/sp_rfc2136.go b/internal/certacme/certifiers/sp_rfc2136.go index c0002d1f7..1cb45cb8b 100644 --- a/internal/certacme/certifiers/sp_rfc2136.go +++ b/internal/certacme/certifiers/sp_rfc2136.go @@ -22,6 +22,9 @@ func init() { TsigAlgorithm: credentials.TsigAlgorithm, TsigKey: credentials.TsigKey, TsigSecret: credentials.TsigSecret, + TsigGssRealm: credentials.TsigGssRealm, + TsigGssUsername: credentials.TsigGssUsername, + TsigGssPassword: credentials.TsigGssPassword, DnsPropagationTimeout: options.DnsPropagationTimeout, DnsTTL: options.DnsTTL, }) diff --git a/internal/domain/access.go b/internal/domain/access.go index 0b4011bfb..92eca9452 100644 --- a/internal/domain/access.go +++ b/internal/domain/access.go @@ -511,11 +511,14 @@ type AccessConfigForRegru struct { } type AccessConfigForRFC2136 struct { - Host string `json:"host"` - Port int32 `json:"port"` - TsigAlgorithm string `json:"tsigAlgorithm,omitempty"` - TsigKey string `json:"tsigKey,omitempty"` - TsigSecret string `json:"tsigSecret,omitempty"` + Host string `json:"host"` + Port int32 `json:"port"` + TsigAlgorithm string `json:"tsigAlgorithm,omitempty"` + TsigKey string `json:"tsigKey,omitempty"` + TsigSecret string `json:"tsigSecret,omitempty"` + TsigGssRealm string `json:"tsigGssRealm,omitempty"` + TsigGssUsername string `json:"tsigGssUsername,omitempty"` + TsigGssPassword string `json:"tsigGssPassword,omitempty"` } type AccessConfigForRuCenter struct { diff --git a/pkg/core/certifier/challengers/dns01/rfc2136/rfc2136.go b/pkg/core/certifier/challengers/dns01/rfc2136/rfc2136.go index 93bf5a2d7..2c2ac9ab6 100644 --- a/pkg/core/certifier/challengers/dns01/rfc2136/rfc2136.go +++ b/pkg/core/certifier/challengers/dns01/rfc2136/rfc2136.go @@ -17,6 +17,9 @@ type ChallengerConfig struct { TsigAlgorithm string `json:"tsigAlgorithm,omitempty"` TsigKey string `json:"tsigKey,omitempty"` TsigSecret string `json:"tsigSecret,omitempty"` + TsigGssRealm string `json:"tsigGssRealm,omitempty"` + TsigGssUsername string `json:"tsigGssUsername,omitempty"` + TsigGssPassword string `json:"tsigGssPassword,omitempty"` DnsPropagationTimeout int `json:"dnsPropagationTimeout,omitempty"` DnsTTL int `json:"dnsTTL,omitempty"` } @@ -39,6 +42,10 @@ func NewChallenger(config *ChallengerConfig) (core.ACMEChallenger, error) { providerConfig.TSIGAlgorithm = config.TsigAlgorithm providerConfig.TSIGKey = config.TsigKey providerConfig.TSIGSecret = config.TsigSecret + providerConfig.TSIGGSSRealm = config.TsigGssRealm + providerConfig.TSIGGSSUsername = config.TsigGssUsername + providerConfig.TSIGGSSPassword = config.TsigGssPassword + providerConfig.TSIGGSSKeytabFile = "" if config.DnsPropagationTimeout != 0 { providerConfig.PropagationTimeout = time.Duration(config.DnsPropagationTimeout) * time.Second } diff --git a/ui/src/components/access/forms/AccessConfigFieldsProviderRFC2136.tsx b/ui/src/components/access/forms/AccessConfigFieldsProviderRFC2136.tsx index becd73ccb..b111177bd 100644 --- a/ui/src/components/access/forms/AccessConfigFieldsProviderRFC2136.tsx +++ b/ui/src/components/access/forms/AccessConfigFieldsProviderRFC2136.tsx @@ -3,6 +3,7 @@ import { Form, Input, InputNumber, Select } from "antd"; import { createSchemaFieldRule } from "antd-zod"; import { z } from "zod"; +import Show from "@/components/Show"; import { isHostname, isPortNumber } from "@/utils/validator"; import { useFormNestedFieldsContext } from "./_context"; @@ -15,8 +16,11 @@ const AccessConfigFormFieldsProviderRFC2136 = () => { [parentNamePath]: getSchema({ i18n }), }); const formRule = createSchemaFieldRule(formSchema); + const formInst = Form.useFormInstance>(); const initialValues = getInitialValues(); + const fieldTsigAlgorithm = Form.useWatch([parentNamePath, "tsigAlgorithm"], formInst); + return ( <>
@@ -46,23 +50,41 @@ const AccessConfigFormFieldsProviderRFC2136 = () => { { label: "HMAC-SHA-256", value: "hmac-sha256." }, { label: "HMAC-SHA-384", value: "hmac-sha384." }, { label: "HMAC-SHA-512", value: "hmac-sha512." }, + { label: "HMAC-SHA-512", value: "hmac-sha512." }, + { label: "GSS-TSIG", value: "gss-tsig." }, ]} placeholder={t("access.form.rfc2136_tsig_algorithm.placeholder")} /> - - - + + + + - - - + + + + + + + + + + + + + + + + + + ); }; @@ -86,6 +108,9 @@ const getSchema = ({ i18n = getI18n() }: { i18n: ReturnType }) = tsigAlgorithm: z.string().nonempty(), tsigKey: z.string().nullish(), tsigSecret: z.string().nullish(), + tsigGssRealm: z.string().nullish(), + tsigGssUsername: z.string().nullish(), + tsigGssPassword: z.string().nullish(), }); }; diff --git a/ui/src/i18n/resources/en/nls.access.json b/ui/src/i18n/resources/en/nls.access.json index ba4dd205a..290d7cc03 100644 --- a/ui/src/i18n/resources/en/nls.access.json +++ b/ui/src/i18n/resources/en/nls.access.json @@ -1162,6 +1162,18 @@ "label": "TSIG authentication secret (Optional)", "placeholder": "Please enter TSIG authentication secret" }, + "rfc2136_tsig_gss_realm": { + "label": "GSS-TSIG Kerberos realm (Optional)", + "placeholder": "Please enter GSS-TSIG Kerberos realm" + }, + "rfc2136_tsig_gss_username": { + "label": "GSS-TSIG Kerberos username (Optional)", + "placeholder": "Please enter GSS-TSIG Kerberos username" + }, + "rfc2136_tsig_gss_password": { + "label": "GSS-TSIG Kerberos password (Optional)", + "placeholder": "Please enter GSS-TSIG Kerberos password" + }, "rucenter_username": { "label": "Ru-Center username", "placeholder": "Please enter Ru-Center username" diff --git a/ui/src/i18n/resources/zh/nls.access.json b/ui/src/i18n/resources/zh/nls.access.json index f3cd1718d..677bddc54 100644 --- a/ui/src/i18n/resources/zh/nls.access.json +++ b/ui/src/i18n/resources/zh/nls.access.json @@ -1162,6 +1162,18 @@ "label": "TSIG 认证密钥 Secret(可选)", "placeholder": "请输入 TSIG 认证密钥 Secret" }, + "rfc2136_tsig_gss_realm": { + "label": "GSS-TSIG Kerberos 领域(可选)", + "placeholder": "请输入 GSS-TSIG Kerberos 领域" + }, + "rfc2136_tsig_gss_username": { + "label": "GSS-TSIG Kerberos 用户名(可选)", + "placeholder": "请输入 GSS-TSIG Kerberos 用户名" + }, + "rfc2136_tsig_gss_password": { + "label": "GSS-TSIG Kerberos 密码(可选)", + "placeholder": "请输入 GSS-TSIG Kerberos 密码" + }, "rucenter_username": { "label": "Ru-Center 用户名", "placeholder": "请输入 Ru-Center 用户名"